Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 81% confidence
- Finding
- The documented purpose is narrow cost analysis, but the behavior reportedly includes scanning the local workspace and installed skill directories and reading multiple configuration locations, including per-agent files. That broader access increases the chance of unintended data exposure, overcollection, and operator surprise, especially because the extra behavior is not clearly disclosed; the broken code path also suggests insufficient review and raises reliability and safety concerns.
